{"id":17044,"date":"2019-11-29T10:52:17","date_gmt":"2019-11-29T18:52:17","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/11\/29\/news-10780\/"},"modified":"2019-11-29T10:52:17","modified_gmt":"2019-11-29T18:52:17","slug":"news-10780","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/29\/news-10780\/","title":{"rendered":"VB2019 video: Thwarting Emotet email conversation thread hijacking with clustering"},"content":{"rendered":"<p>Having returned from its summer break, Emotet is once again being used as the first stage of many often prominent and costly malware infections. A detailed analysis of the malware was given in a <a title=\"VB2019 paper: Exploring Emotet, an elaborate everyday enigma\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2019\/10\/vb2019-paper-exploring-emotet-elaborate-everyday-enigma\/\">paper<\/a> presented at VB2019 by Sophos researcher Luca Nagy.<\/p>\n<p>But Emotet isn&#8217;t just a very clever piece of malware. It also uses very clever techniques to evade email security products\u00a0\u2013 something we have <a title=\"Emotet continues to bypass many email security products\" href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/emotet-continues-bypass-many-email-security-products\/\">noticed<\/a> many times in our lab.<\/p>\n<p>One such technique is the hijacking of existing email threads, which makes it harder to filter the emails and makes recipients more likely to think the emails are legitimate. This thread hijacking was the subject of a last-minute paper presented at VB2019 by ZEROSPAM researchers Pierre-Luc Vaudry and Olivier Coutu, who also explained how clustering helped them detect such campaigns.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/5415\/7502\/2738\/emotet_clustering_dbscan.png\" alt=\"emotet_clustering_dbscan.png\" width=\"460\" height=\"389\" \/><\/p>\n<p>Today, we have uploaded the video of Pierre-Luc and Olivier&#8217;s talk in London to our <em>YouTube<\/em> channel.<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/A4Hm-NoDXCs\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p>\u00a0<\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-video-thwarting-emotet-email-conversation-thread-hijacking-clustering\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/5415\/7502\/2738\/emotet_clustering_dbscan.png\"\/><br \/>                                 At VB2019 in London, ZEROSPAM researchers Pierre-Luc Vaudry and Olivier Coutu discussed how email clustering could be used to detect malicious Emotet emails that hijacked existing email threads. Today we publish the recording of their presentation.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-video-thwarting-emotet-email-conversation-thread-hijacking-clustering\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-17044","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17044"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17044\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17044"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}